Evnly legal
Privacy Policy
Effective date: 16 September 2026
This Privacy Policy explains what evnly collects, why we use it, who receives it, how long we keep it, and the choices available to you.
1. Who is responsible for your data
For data processed through evnly, the controller is Jerome Bei, operating evnly. Contact: support@jerome.photo.
This policy applies to the evnly website and mobile applications, including the authentication screen, group expense features, receipt or file features, notifications, and support interactions.
2. Data we collect
Account and identity data
When you sign in with Google or Apple, we receive the provider identity needed to authenticate you, such as a provider user identifier, display name, email address or Apple private-relay address, profile image where available, and the Firebase user identifier. We do not ask for or store a Google or Apple password.
Group and expense data
We process the information you and other group members enter, including group names, memberships, invitations, display names, expenses, descriptions, amounts, currencies, dates, payers, splits, exchange rates, settlements, comments, reminders, change history, and related identifiers.
Receipts and other files
If you use a receipt or file feature, we process the image, PDF, or other file you choose to upload, together with its metadata and the group or expense to which it is attached. Do not upload passwords, payment-card details, government identifiers, health information, or other information that evnly does not need.
Technical, security, and activity data
We process information needed to operate and protect the service, such as IP address, browser or device information, timestamps, request identifiers, route and status information, authentication events, error details, and meaningful user activity such as creating or editing an expense, changing a split, joining a group, exporting data, or accessing a receipt.
Our structured logging is designed to exclude authentication tokens, authorization headers, cookies, private keys, full request bodies, receipt bytes, receipt contents, and password fields. We do not use evnly to record keystrokes or raw screen recordings.
Support and communications
If you contact us, we process the message and contact details you provide so we can respond, investigate issues, and keep a support record.
3. Why we use data
- Provide the service: authenticate you, create your evnly profile, synchronize groups, calculate balances, store receipts, and deliver features you request.
- Secure and maintain the service: prevent abuse, troubleshoot failures, investigate suspicious activity, protect accounts, enforce access rules, and keep reliable audit records.
- Communicate with you: respond to support, send service messages, and deliver reminders or notifications you enable.
- Meet legal obligations: comply with law, lawful requests, accounting requirements, and the establishment or defense of legal claims.
- Improve evnly: understand reliability and feature use through aggregated or minimized activity data. We do not sell personal information or use it for cross-context behavioral advertising.
4. Legal bases
Where the GDPR or a similar law applies, we process data because it is necessary to perform our contract with you, because we have a legitimate interest in operating and securing evnly, because we need to comply with a legal obligation, or because you have consented to an optional activity such as a device permission or non-essential communication. Where we rely on consent, you can withdraw it without affecting processing that occurred before withdrawal.
5. Who receives data
- Other group members: people who have access to a group can see the group information shared there. This is the central purpose of evnly.
- Google and Apple: the identity provider you choose processes authentication under its own terms and privacy policy.
- Firebase and Google Cloud: Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Hosting, and Cloud Logging process data on our instructions or as necessary to provide their services.
- Service providers: we may use carefully selected providers for infrastructure, email, push notifications, monitoring, support, or payments when a feature requires them. They may process only the information needed for their service.
- Legal and business recipients: we may disclose data when required by law or when reasonably necessary to protect users, the service, or legal rights, or during a merger, acquisition, financing, or sale of assets.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
6. International transfers
Our infrastructure providers may process data in the United States and other countries where they operate. Those countries may have different data-protection rules. Where required, we use appropriate safeguards for international transfers, such as an adequacy decision or approved contractual safeguards, and we require providers to protect data under their applicable agreements.
7. Retention and deletion
We keep account and group data while your account or the relevant group remains active, unless a longer period is needed for security, legal, dispute, backup, or record-integrity purposes. We keep operational logs for the period configured for the relevant environment and limit them to what is needed for reliability and security. Security and financial-audit records may be retained for up to 12 months when needed to investigate abuse, disputes, or changes to shared records.
When you request account deletion, we delete or anonymize personal profile data and private user data within a reasonable period, normally 30 days, subject to data that must remain in backups or is needed to preserve another group member’s expense history, prevent fraud, resolve disputes, or comply with law. We do not use retained data for new purposes.
8. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, restrict, or object to processing of your personal data; receive a portable copy; withdraw consent; and complain to a data-protection authority.
California residents may also have rights to know, delete, correct, limit certain uses of sensitive personal information, opt out of sale or sharing, and receive equal service. We do not sell or share personal information for cross-context behavioral advertising. We will not discriminate against you for exercising applicable rights.
To exercise a right, email support@jerome.photo with the request and the account email or provider identity you use with evnly. We may ask for reasonable information to verify the request and protect another person’s data. We normally respond within one month for GDPR requests, subject to lawful extensions, and within the time required by applicable local law.
9. Cookies and local storage
evnly uses necessary browser storage and cookies for Firebase authentication, redirect security, session continuity, and basic operation. The website also stores your theme preference locally when you choose Light or Dark. We do not currently use advertising cookies or third-party behavioral advertising trackers. Google, Apple, and Firebase may use their own cookies or similar technologies when their authentication or infrastructure pages are involved.
10. Children
evnly is not directed to children under 13. If you believe a child has provided personal data to evnly, contact us so we can investigate and remove it where appropriate.
11. Security
We use access controls, Firebase Security Rules, provider authentication, encryption provided by our infrastructure providers, secret redaction, and operational monitoring appropriate to the service. No transmission or storage system is completely secure, so do not upload information that evnly does not need.
12. Changes to this policy
We may update this policy as evnly changes or legal requirements develop. We will publish the new version on this page and update the effective date. If a change materially affects your rights or how we use your data, we will provide additional notice where required.